Back

CVE-2017-5334

CRITICAL

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.

Published: Mar 24, 2017 Modified: Jun 17, 2026
CWE-415

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (11)

Vendor Product Version
opensuse leap 42.1
opensuse leap 42.2
gnu gnutls *
gnu gnutls 3.5.0
gnu gnutls 3.5.1
gnu gnutls 3.5.2
gnu gnutls 3.5.3
gnu gnutls 3.5.4
gnu gnutls 3.5.5
gnu gnutls 3.5.6
gnu gnutls 3.5.7

GitHub Security Advisory GHSA-xwcr-3xw9-7333

Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 32.75%

Top 2% most likely to be exploited

Threat Score 49 / 100

Data Sources

NVD EPSS GitHub